OSTicket Multiple Input Validation Vulnerabilities
BID:14127
Info
OSTicket Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 14127 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2154 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2005 12:00AM |
| Updated: | Mar 28 2007 09:43PM |
| Credit: | Discovery is credited to edisan & foster. |
| Vulnerable: |
osTicket osTicket STS 1.3 beta osTicket osTicket STS 1.2.7 osTicket osTicket STS 1.2 eTicket eTicket 1.5.4 |
| Not Vulnerable: |
osTicket osTicket STS 1.3.1 eTicket eTicket 1.5.5 |
Discussion
OSTicket Multiple Input Validation Vulnerabilities
osTicket is affected by multiple input-validation vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
The following specific issues were identified:
- An SQL-injection vulnerability. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
- A local file-include vulnerability. An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
osTicket 1.3.1 beta and prior versions are affected.
osTicket is affected by multiple input-validation vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
The following specific issues were identified:
- An SQL-injection vulnerability. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
- A local file-include vulnerability. An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
osTicket 1.3.1 beta and prior versions are affected.
Exploit / POC
OSTicket Multiple Input Validation Vulnerabilities
No exploit is required.
The following proof of concept is available for the file-include issue:
http://www.example.com/osticket/view.php?inc=x
No exploit is required.
The following proof of concept is available for the file-include issue:
http://www.example.com/osticket/view.php?inc=x
Solution / Fix
OSTicket Multiple Input Validation Vulnerabilities
Solution:
The vendor released version 1.3.1 to address this issue. Please contact the vendor for information on obtaining and applying fixes.
Solution:
The vendor released version 1.3.1 to address this issue. Please contact the vendor for information on obtaining and applying fixes.
References
OSTicket Multiple Input Validation Vulnerabilities
References:
References:
- eTicket Homepage (eTicket)
- osTicket Homepage (osTicket)
- osTicket: Security Alert (osTicket)
- Re: Multiple Vulnerabilities In osTicket (eTicket)
- [SECURITY ALERT] osTicket bugs ([email protected])